Sign inSign up
GitLab Runner

dhi.io/gitlab-runner

GitLab Runner 18.x

CIS
linux/amd64
debian 13
Tags:

18, 18-debian, 18-debian13, 18.11, 18.11-debian, 18.11-debian13, 18.11.4, 18.11.4-debian, 18.11.4-debian13

Index digest:

sha256:ab784fbf8f5e18a5ea3e2b7955915b66b27bf62f172b794af5e238fa9d118d5f

Manifest digest:

sha256:a075819a3215be04241d1be1ab7b575c87488ef657b2183f05b31595d8a47a85

Size

81.16 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
1
11
0

Support

Ends Jul 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-runner:18

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-runner:18 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-runner@sha256:468be0d7083b5067ff2d82a1ff7b812a7d045ebd857e5c95b906ccf91cbc2f22
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-runner@sha256:1bfcbfd98eccc1fbcd5d9a8926b036fe38718322863daf9aff02ce05ce3b39e8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-runner@sha256:d6867dd50e153b0bbe979cfe929e938dd0847adbe367ad3d638484304f9a89f4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-runner@sha256:56be726d926cc0215c8e48552782171fa273c7564b1e96c44f957410fac8b182
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-runner@sha256:f2f7563b3c4415377b7cd1db315ff17f2d29f46d5b33c9fda19896f75c1c5067
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-runner@sha256:54cd45e1829cb08f706a7d856340c2f8adb89bbdd795a6973eb9331ef0307556
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-runner@sha256:5f7815b2c769361af7e684ae144a64b45750f70adc4d341932653ba8373c4124
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-runner@sha256:87abb24335dd4fdc025e24056bed79e94f52201da0372fa6ba2a142edf766360
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-runner@sha256:e6bc2b6863e397d16530d56e838d1f76e1fda44bf60e9ceefef1aaaabdc46f5a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-runner@sha256:382b5465a5f4ca965f3d9eab44b7672e766419fe9bd7005af5a791018543e20e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-runner@sha256:6198089a0de7a6ae5e664c8a5c2491f6d57da5d1dbdb1f82931ece4ae8e449ea
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-runner@sha256:a236b5d931d16ab0ecfdcd4a71d8c9531697baee61f7d7a54b20f8c39e74ddc9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-runner@sha256:a4825192ac44cb0f6e31382c1d12da2830022ed56bb4b308cdef2f09baae1665
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-runner@sha256:0b6805ac7e3233f3f0238cf9b7587292df202077863a19c2605f4ea6a6c02d9c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-runner@sha256:ee214a397755990e053b3bb8d2c32872b6fc5005af1becff9bab0e0fdd7cd4c4